Cubist Role Access Tokens API
The Role Access Tokens API from Cubist — 2 operation(s) for role access tokens.
The Role Access Tokens API from Cubist — 2 operation(s) for role access tokens.
openapi: 3.0.3
info:
title: CubeSigner Account Role Access Tokens API
description: The CubeSigner management and signing service.
contact:
name: Cubist Inc.
email: hello@cubist.dev
version: v0.1.0
servers:
- url: https://gamma.signer.cubist.dev
description: Testing and staging environment
- url: https://prod.signer.cubist.dev
description: Production environment
security:
- Cognito: []
tags:
- name: Role Access Tokens
paths:
/v0/org/{org_id}/roles/{role_id}/tokens:
post:
tags:
- Role Access Tokens
summary: Create Token
description: 'Create Token
Creates a new access token for a given role (to be used as "API Key" for all signing actions).
The `restricted_actions` field on the [Role] determines the membership role that is required to
create tokens.'
operationId: createRoleToken
parameters:
- name: org_id
in: path
description: Name or ID of the desired Org
required: true
schema:
type: string
example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
- name: role_id
in: path
description: Name or ID of the desired Role
required: true
schema:
type: string
example: Role#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/CreateTokenRequest'
required: true
responses:
'200':
$ref: '#/components/responses/NewSessionResponse'
default:
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
security:
- SignerAuth:
- manage:session:create
/v0/org/{org_id}/token/keys:
get:
tags:
- Role Access Tokens
summary: Get Token-Accessible Keys
description: 'Get Token-Accessible Keys
Retrieves the keys that a user or role session can access.'
operationId: listTokenKeys
parameters:
- name: org_id
in: path
description: Name or ID of the desired Org
required: true
schema:
type: string
example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
responses:
'200':
$ref: '#/components/responses/KeyInfos'
default:
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
security:
- SignerAuth:
- manage:key:get
components:
schemas:
EpochDateTime:
type: integer
format: int64
description: 'DateTime measured in seconds since unix epoch.
A wrapper type for serialization that encodes a [`SystemTime`] as a [`u64`]
representing the number of seconds since [`SystemTime::UNIX_EPOCH`].'
minimum: 0
MfaRequiredArgs:
type: object
required:
- id
- ids
- org_id
properties:
id:
type: string
description: Always set to first MFA id from `Self::ids`
ids:
type: array
items:
type: string
minLength: 1
description: Non-empty MFA request IDs
org_id:
type: string
description: Organization id
policy_eval_tree:
description: Optional policy evaluation tree (included in signer responses, when requested)
nullable: true
session:
allOf:
- $ref: '#/components/schemas/NewSessionResponse'
nullable: true
B32:
type: string
description: Wrapper around a zeroizing 32-byte fixed-size array
KeyDerivationInfo:
type: object
description: Derivation-related metadata for keys derived from a long-lived mnemonic
required:
- mnemonic_id
- derivation_path
properties:
derivation_path:
type: string
description: The derivation path used to derive this key
mnemonic_id:
type: string
description: The mnemonic-id of the key's parent mnemonic
CoinbaseApiPropertiesPatch:
type: object
description: 'Wire-format patch payload for [`KeyProperties::CoinbaseApi`].
Every field follows the same per-field PATCH semantics: a missing field
leaves the existing value alone, a JSON `null` clears it, and a value sets it.'
properties:
api_key_id:
type: string
description: 'Identifier of the Coinbase API key this key authenticates as. Plain
(non-secret) value; appears in JWT `kid`/`sub` claims.'
nullable: true
portfolio_name:
type: string
description: Coinbase portfolio name.
nullable: true
portfolio_uuid:
type: string
description: Coinbase portfolio UUID.
nullable: true
ScopeSet:
oneOf:
- type: string
description: All scopes
enum:
- All
- type: object
required:
- AllExcept
properties:
AllExcept:
type: array
items:
$ref: '#/components/schemas/Scope'
description: All scopes except these (including those transitively implied).
- type: object
required:
- AllOf
properties:
AllOf:
type: array
items:
$ref: '#/components/schemas/Scope'
description: All of these scopes (including those transitively implied).
description: A set of scopes.
CommonFields:
allOf:
- type: object
description: 'Versioning fields (e.g., version number, creation time, and last modified times)
that are common to different types of resources.'
properties:
created:
allOf:
- $ref: '#/components/schemas/EpochDateTime'
nullable: true
last_modified:
allOf:
- $ref: '#/components/schemas/EpochDateTime'
nullable: true
version:
type: integer
format: int64
description: Version of this object
minimum: 0
- type: object
properties:
edit_policy:
$ref: '#/components/schemas/EditPolicy'
metadata:
description: 'User-defined metadata. When rendering (e.g., in the browser) you should treat
it as untrusted user data (and avoid injecting metadata into HTML directly) if
untrusted users can create/update keys (or their metadata).'
description: 'Fields that are common to different types of resources such as keys, roles, etc.
Includes versioning fields plus metadata, edit policy, etc.'
AcceptedValue:
oneOf:
- type: object
required:
- SignDryRun
properties:
SignDryRun:
$ref: '#/components/schemas/SignDryRunArgs'
- type: object
required:
- BinanceDryRun
properties:
BinanceDryRun:
$ref: '#/components/schemas/BinanceDryRunArgs'
- type: object
required:
- BybitDryRun
properties:
BybitDryRun:
$ref: '#/components/schemas/BybitDryRunArgs'
- type: object
required:
- CoinbaseDryRun
properties:
CoinbaseDryRun:
$ref: '#/components/schemas/CoinbaseDryRunArgs'
- type: object
required:
- MfaRequired
properties:
MfaRequired:
$ref: '#/components/schemas/MfaRequiredArgs'
description: Different responses we return for success status codes.
RatchetConfig:
type: object
properties:
auth_lifetime:
type: integer
format: int64
description: 'The lifetime (in seconds) of auth tokens for this session.
Auth tokens can be refreshed (renewed) using a valid (unexpired)
refresh token, but not beyond the session lifetime.'
default: 300
example: 3600
minimum: 0
grace_lifetime:
type: integer
format: int64
description: 'The amount of time (in seconds) that an auth token for this session remains
valid after it has been refreshed and a new auth token has been issued. This
helps to address concurrency hazards, for example, if one thread makes requests
with auth token while another refreshes it.'
default: 30
example: 30
minimum: 0
refresh_lifetime:
type: integer
format: int64
description: 'The lifetime (in seconds) of refresh tokens for this session.
If this value is shorter than the session lifetime, inactive sessions
will become invalid once the auth and refresh tokens have both expired.'
default: 86400
example: 43200
minimum: 0
session_lifetime:
type: integer
format: int64
description: 'The lifetime (in seconds) of the session.
The session cannot be extended beyond its original lifetime.'
default: 31536000
example: 86400
minimum: 0
NotFoundErrorCode:
type: string
enum:
- UriSegmentMissing
- UriSegmentInvalid
- TotpNotConfigured
- FidoKeyNotFound
- FidoChallengeNotFound
- TotpChallengeNotFound
- UserExportRequestNotFound
- UserExportCiphertextNotFound
- OrgExportCiphertextNotFound
- UploadObjectNotFound
- PolicySecretNotFound
- BucketMetaNotFound
- TimestreamDisabled
- CustomChainNotFound
- InvitationNotFound
- TransactionNotFound
- EmailConfigNotFound
HttpRequestCmp:
oneOf:
- type: string
description: The requests must match exactly. Any given MFA receipt can be used at most once.
enum:
- Eq
- type: object
required:
- EvmTx
properties:
EvmTx:
$ref: '#/components/schemas/EvmTxCmp'
- type: object
required:
- SolanaTx
properties:
SolanaTx:
$ref: '#/components/schemas/SolanaTxCmp'
description: How to compare HTTP requests when verifying MFA receipt (see [MfaRequest::verify_request])
BadGatewayErrorCode:
type: string
enum:
- Generic
- CustomChainRpcError
- EsploraApiError
- SentryApiError
- CallWebhookError
- OAuthProviderError
- OidcDisoveryFailed
- OidcIssuerJwkEndpointUnavailable
- SmtpServerUnavailable
SolanaTxCmp:
type: object
properties:
ignore_blockhash:
type: boolean
description: Whether the 'recent_blockhash' property of the Solana transaction is allowed to be different.
InternalErrorCode:
type: string
enum:
- NoMaterialId
- InvalidAuditLogEntry
- UnexpectedCheckerRule
- UnresolvedPolicyReference
- UnexpectedAclAction
- FidoKeyAssociatedWithMultipleUsers
- ClaimsParseError
- InvalidThrottleId
- InvalidEmailAddress
- EmailTemplateRender
- OidcIdentityHeaderMissing
- OidcIdentityParseError
- SystemTimeError
- PasswordHashParseError
- SendMailError
- ReqwestError
- EmailConstructionError
- TsWriteError
- TsQueryError
- DbQueryError
- DbGetError
- DbDeleteError
- DbPutError
- DbUpdateError
- SerdeError
- TestAndSetError
- DbGetItemsError
- DbWriteError
- CubistSignerError
- CwListMetricsError
- CwPutMetricDataError
- GetAwsSecretError
- SecretNotFound
- KmsGenerateRandomError
- MalformedTotpBytes
- KmsGenerateRandomNoResponseError
- CreateKeyError
- ParseDerivationPathError
- SplitSignerError
- CreateImportKeyError
- CreateEotsNoncesError
- EotsSignError
- BabylonCovSignError
- CognitoDeleteUserError
- CognitoListUsersError
- CognitoGetUserError
- MissingUserEmail
- CognitoResendUserInvitation
- CognitoSetUserPasswordError
- GenericInternalError
- AssumeRoleWithoutEvidence
- OidcAuthWithoutOrg
- MissingKeyMetadata
- KmsEnableKeyError
- KmsDisableKeyError
- LambdaInvokeError
- LambdaNoResponseError
- LambdaFailure
- LambdaUnparsableResponse
- SerializeEncryptedExportKeyError
- DeserializeEncryptedExportKeyError
- ReEncryptUserExport
- S3UploadError
- S3DownloadError
- S3CopyError
- S3ListObjectsError
- S3DeleteObjectsError
- S3BuildError
- S3PresignedUrlError
- ManagedStateMissing
- InternalHeaderMissing
- InvalidInternalHeaderValue
- RequestLocalStateAlreadySet
- OidcOrgMismatch
- OidcIssuerInvalidJwk
- InvalidPkForMaterialId
- SegwitTweakFailed
- UncheckedOrg
- SessionOrgIdMissing
- AvaSignCredsMissing
- AvaSignSignatureMissing
- ExpectedRoleSession
- InvalidThirdPartyIdentity
- CognitoGetUser
- SnsSubscribeError
- SnsUnsubscribeError
- SnsGetSubscriptionAttributesError
- SnsSubscriptionAttributesMissing
- SnsSetSubscriptionAttributesError
- SnsPublishBatchError
- InconsistentMultiValueTestAndSet
- MaterialIdError
- InvalidBtcAddress
- HistoricalTxBodyMissing
- InvalidOperation
- ParentOrgNotFound
- OrgParentLoop
- ResolvedParentOrgWithNoScopeCeiling
- InvalidUploadObjectId
- PolicyEngineNotFound
- PolicyEngineError
- PolicySecretsEncryptionError
- CreatePolicyImportKeyError
- InvalidAlias
- EmptyUpdateModifiedObject
- EmptyUpdateModifiedActions
- DbContactAddressesInvalid
- InvalidEvmSigedRlp
- InvalidErc20Data
- InvalidRpcUrl
SignerErrorCode:
oneOf:
- $ref: '#/components/schemas/SignerErrorOwnCodes'
- $ref: '#/components/schemas/AcceptedValueCode'
- $ref: '#/components/schemas/BadRequestErrorCode'
- $ref: '#/components/schemas/BadGatewayErrorCode'
- $ref: '#/components/schemas/NotFoundErrorCode'
- $ref: '#/components/schemas/ForbiddenErrorCode'
- $ref: '#/components/schemas/UnauthorizedErrorCode'
- $ref: '#/components/schemas/PreconditionErrorCode'
- $ref: '#/components/schemas/TimeoutErrorCode'
- $ref: '#/components/schemas/ConflictErrorCode'
- $ref: '#/components/schemas/InternalErrorCode'
EvmTxCmp:
type: object
properties:
grace:
type: integer
format: int64
description: 'To prevent replay attacks, any given MFA receipt is normally allowed to be used only once.
In this case, however, because EVM transactions already have a replay prevention mechanism
(namely the ''nonce'' property), we allow the user to specify a grace period (in seconds) to
indicate how long an MFA receipt should remain valid after its first use.
Note that we allow both ''grace'' and ''ignore_nonce'' to be set because once an MFA request
enters its grace period we unconditionally set its ''ignore_nonce'' property to ''false'' to
ensure that any subsequent requests that claim the same receipt must sign for the same
nonce as the request we signed originally with that receipt.
Also note that the grace period cannot extend the lifetime of an MFA request beyond its
original expiration date.
The grace period must not be greater than 30 days.'
nullable: true
minimum: 0
ignore_gas:
type: boolean
description: Whether the 'gas' property of the EVM transaction is allowed to be different.
ignore_nonce:
type: boolean
description: Whether the 'nonce' property of the EVM transaction is allowed to be different.
EvmTxDepositErrorCode:
type: string
enum:
- EvmTxDepositReceiverMismatch
- EvmTxDepositEmptyData
- EvmTxDepositEmptyChainId
- EvmTxDepositEmptyReceiver
- EvmTxDepositUnexpectedValue
- EvmTxDepositUnexpectedDataLength
- EvmTxDepositNoAbi
- EvmTxDepositNoDepositFunction
- EvmTxDepositUnexpectedFunctionName
- EvmTxDepositUnexpectedValidatorKey
- EvmTxDepositInvalidValidatorKey
- EvmTxDepositMissingDepositArg
- EvmTxDepositWrongDepositArgType
- EvmTxDepositValidatorKeyNotInRole
- EvmTxDepositUnexpectedWithdrawalCredentials
- EvmTxDepositUnresolvedRole
- EvmTxDepositInvalidDepositEncoding
KeyInfo:
allOf:
- $ref: '#/components/schemas/CommonFields'
- type: object
required:
- key_type
- key_id
- material_id
- purpose
- enabled
- owner
- public_key
- policy
properties:
derivation_info:
allOf:
- $ref: '#/components/schemas/KeyDerivationInfo'
nullable: true
enabled:
type: boolean
description: Whether the key is enabled (only enabled keys may be used for signing)
key_id:
type: string
description: 'The id of the key: "Key#" followed by a unique identifier specific to
the type of key (such as a public key for BLS or an ethereum address for Secp)'
example: Key#0x8e3484687e66cdd26cf04c3647633ab4f3570148
key_type:
$ref: '#/components/schemas/KeyType'
material_id:
type: string
description: A unique identifier specific to the type of key, such as a public key or an ethereum address
example: '0x8e3484687e66cdd26cf04c3647633ab4f3570148'
owner:
type: string
description: Owner of the key
example: User#c3b9379c-4e8c-4216-bd0a-65ace53cf98f
policy:
type: array
items: {}
description: Key policy
example:
- AllowRawBlobSigning
- RequireMfa:
count: 1
properties:
allOf:
- $ref: '#/components/schemas/KeyPropertiesPatch'
nullable: true
provenance:
type: string
description: The key provenance.
nullable: true
public_key:
type: string
description: 'Hex-encoded, serialized public key. The format used depends on the key type:
- Secp256k1 keys use 65-byte uncompressed SECG format;
- Stark keys use 33-byte compressed SECG format;
- BLS keys use 48-byte compressed BLS12-381 (ZCash) format;
- Ed25519 keys use the canonical 32-byte encoding specified in RFC 8032.'
example: '0x04d2688b6bc2ce7f9879b9e745f3c4dc177908c5cef0c1b64cff19ae7ff27dee623c64fe9d9c325c7fbbc748bbd5f607ce14dd83e28ebbbb7d3e7f2ffb70a79431'
purpose:
type: string
description: The purpose for which the key can be used (e.g., chain id for which the key is allowed to sign messages)
example: Eth2Validator(1)
region:
type: string
description: The region affinity for this key
EditPolicy:
type: object
description: 'A policy which governs when and who is allowed to update the entity this policy is
attached to (e.g., a role or a key).
When attached to a role, by default, this policy applies to role deletion and all
role updates (including adding/removing keys and users); in terms of scopes,
it applies to `manage:role:update:*` and `manage:role:delete`.
When attached to a key, by default, this policy applies to key deletion, all
key updates, and adding/removing that key to/from a role; in terms of scopes,
it applies to `manage:key:update:*`, `manage:key:delete`, `manage:role:update:key:*`.
This default can be changed by setting the `applies_to_scopes` property.'
properties:
applies_to_scopes:
$ref: '#/components/schemas/ScopeSet'
mfa:
allOf:
- $ref: '#/components/schemas/MfaPolicy'
nullable: true
time_lock_until:
allOf:
- $ref: '#/components/schemas/EpochDateTime'
nullable: true
OperationKind:
type: string
description: All different kinds of sensitive operations
enum:
- AvaSign
- AvaChainTxSign
- BabylonCovSign
- BabylonRegistration
- BabylonStaking
- BinanceSubToMaster
- BinanceSubToSub
- BinanceUniversalTransfer
- BinanceSubAccountAssets
- BinanceAccountInfo
- BinanceSubAccountTransferHistory
- BinanceUniversalTransferHistory
- BinanceWithdraw
- BinanceWithdrawHistory
- BinanceDeposit
- BinanceDepositHistory
- BinanceListSubAccounts
- BinanceCoinInfo
- BlobSign
- BtcMessageSign
- BtcSign
- BybitQueryUser
- BybitQuerySubMembers
- BybitQueryCoinsBalance
- BybitQueryDepositAddress
- BybitUniversalTransfer
- BybitWithdraw
- BybitWithdrawals
- CoinbaseListAccounts
- CoinbaseListPortfolios
- CoinbaseMoveFunds
- DiffieHellman
- PsbtSign
- TaprootSign
- Eip191Sign
- Eip712Sign
- Eip7702Sign
- EotsNonces
- EotsSign
- Eth1Sign
- Eth2Sign
- Eth2Stake
- Eth2Unstake
- SolanaSign
- SuiSign
- TendermintSign
- RoleUpdate
ErrorResponse:
type: object
description: The structure of ErrorResponse must match the response template that AWS uses
required:
- message
- error_code
properties:
accepted:
allOf:
- $ref: '#/components/schemas/AcceptedValue'
nullable: true
error_code:
$ref: '#/components/schemas/SignerErrorCode'
message:
type: string
description: Error message
policy_eval_tree:
description: Optional policy evaluation tree (included in signer responses, when requested)
nullable: true
request_id:
type: string
description: Optional request identifier
PreconditionErrorOwnCodes:
type: string
enum:
- FailOnMfaRequired
- KeyRegionLocked
- KeyRegionChangedRecently
- MfaRegionLocked
- Eth2ProposerSlotTooLow
- Eth2AttestationSourceEpochTooLow
- Eth2AttestationTargetEpochTooLow
- Eth2ConcurrentBlockSigning
- Eth2ConcurrentAttestationSigning
- Eth2MultiDepositToNonGeneratedKey
- Eth2MultiDepositUnknownInitialDeposit
- Eth2MultiDepositWithdrawalAddressMismatch
- ConcurrentSigningWhenTimeLimitPolicyIsDefined
- BabylonEotsConcurrentSigning
- TendermintStateError
- TendermintConcurrentSigning
- MfaApprovalsNotYetValid
ClientSessionInfo:
type: object
description: 'Session information sent to the client.
This struct works in tandem with its server-side counterpart [`SessionData`].'
required:
- session_id
- auth_token
- refresh_token
- epoch
- epoch_token
- auth_token_exp
- refresh_token_exp
properties:
auth_token:
type: string
description: Token to use for authorization.
auth_token_exp:
$ref: '#/components/schemas/EpochDateTime'
epoch:
type: integer
format: int32
description: Epoch at which the token was last refreshed
minimum: 0
epoch_token:
$ref: '#/components/schemas/B32'
refresh_token:
type: string
description: Token to use for refreshing the `(auth, refresh)` token pair
refresh_token_exp:
$ref: '#/components/schemas/EpochDateTime'
session_id:
type: string
description: Session ID
PolicyErrorOwnCodes:
type: string
enum:
- Inapplicable
- SuiTxReceiversDisallowedTransactionKind
- SuiTxReceiversDisallowedTransferAddress
- SuiTxReceiversDisallowedCommand
- BtcTxDisallowedOutputs
- BtcSignatureExceededValue
- BtcValueOverflow
- BtcSighashTypeDisallowed
- Eip7702AddressMismatch
- EvmTxReceiverMismatch
- EvmTxChainIdMismatch
- EvmTxSenderMismatch
- EvmTxExceededValue
- EvmTxExceededGasCost
- EvmTxGasCostUndefined
- EvmDataDisallowed
- Erc20DataInvalid
- EvmContractAddressUndefined
- EvmContractChainIdUndefined
- EvmDataNotDefined
- EvmDataInvalid
- EvmContractNotInAllowlist
- Erc20ExceededTransferLimit
- Erc20ReceiverMismatch
- Erc20ExceededApproveLimit
- Erc20SpenderMismatch
- EvmFunctionNotInAllowlist
- EvmFunctionCallInvalid
- EvmFunctionCallDisallowedArg
- PolicyDisjunctionError
- PolicyNegationError
- Eth2ExceededMaxUnstake
- Eth2ConcurrentUnstaking
- NotInIpv4Allowlist
- NotInOriginAllowlist
- NotInOperationAllowlist
- InvalidSourceIp
- RawSigningNotAllowed
- DiffieHellmanExchangeNotAllowed
- Eip712SigningNotAllowed
- OidcSourceNotAllowed
- NoOidcAuthSourcesDefined
- AddKeyToRoleDisallowed
- KeysAlreadyInRole
- KeyInMultipleRoles
- KeyAccessError
- RequireRoleSessionKeyAccessError
- BtcMessageSigningNotAllowed
- Eip191SigningNotAllowed
- Eip7702SigningNotAllowed
- TaprootSigningDisallowed
- SegwitSigningDisallowed
- PsbtSigningDisallowed
- BabylonStakingDisallowed
- TimeLocked
- CelPolicyDenied
- BabylonStakingNetwork
- BabylonStakingParamsVersion
- BabylonStakingExplicitParams
- BabylonStakingStakerPk
- BabylonStakingFinalityProviderPk
- BabylonStakingLockTime
- BabylonStakingValue
- BabylonStakingChangeAddress
- BabylonStakingFee
- BabylonStakingWithdrawalAddress
- BabylonStakingBbnAddress
- SolanaInstructionCountLow
- SolanaInstructionCountHigh
- SolanaNotInInstructionAllowlist
- SolanaInstructionMismatch
- WasmPoliciesDisabled
- WasmPolicyDenied
- WasmPolicyFailed
- WebhookPoliciesDisabled
- DeniedByWebhook
- ExplicitlyDenied
ExplicitScope:
type: string
title: ExplicitScope
description: Explicitly named scopes for accessing CubeSigner APIs
enum:
- sign:*
- sign:ava
- sign:binance:*
- sign:binance:subToMaster
- sign:binance:subToSub
- sign:binance:universalTransfer
- sign:binance:subAccountAssets
- sign:binance:accountInfo
- sign:binance:subAccountTransferHistory
- sign:binance:universalTransferHistory
- sign:binance:withdraw
- sign:binance:withdrawHistory
- sign:binance:deposit
- sign:binance:depositHistory
- sign:binance:listSubAccounts
- sign:binance:coinInfo
- sign:bybit:*
- sign:bybit:queryUser
- sign:bybit:querySubMembers
- sign:bybit:queryCoinsBalance
- sign:bybit:queryDepositAddress
- sign:bybit:universalTransfer
- sign:bybit:withdraw
- sign:bybit:withdrawals
- sign:coinbase:*
- sign:coinbase:accounts:list
- sign:coinbase:portfolios:list
- sign:coinbase:funds:move
- sign:blob
- sign:diffieHellman
- sign:btc:*
- sign:btc:segwit
- sign:btc:taproot
- sign:btc:psbt:*
- sign:btc:psbt:doge
- sign:btc:psbt:legacy
- sign:btc:psbt:segwit
- sign:btc:psbt:taproot
- sign:btc:psbt:ltcSegwit
- sign:btc:message:*
- sign:btc:message:segwit
- sign:btc:message:legacy
- sign:babylon:*
- sign:babylon:eots:*
- sign:babylon:eots:nonces
- sign:babylon:eots:sign
- sign:babylon:staking:*
- sign:babylon:staking:deposit
- sign:babylon:staking:unbond
- sign:babylon:staking:withdraw
- sign:babylon:staking:slash
- sign:babylon:registration
- sign:babylon:covenant
- sign:evm:*
- sign:evm:tx
- sign:evm:eip191
- sign:evm:eip712
- sign:evm:eip7702
- sign:eth2:*
- sign:eth2:validate
- sign:eth2:stake
- sign:eth2:unstake
- sign:solana
- sign:sui
- sign:tendermint
- sign:mmi
- manage:*
- manage:readonly
- manage:email:*
- manage:email:get
- manage:email:update
- manage:email:delete
- manage:mfa:*
- manage:mfa:readonly
- manage:mfa:list
- manage:mfa:vote:*
- manage:mfa:vote:cs
- manage:mfa:vote:email
- manage:mfa:vote:fido
- manage:mfa:vote:totp
- manage:mfa:register:*
- manage:mfa:register:fido
- manage:mfa:register:totp
- manage:mfa:register:email
- manage:mfa:unregister:*
- manage:mfa:unregister:fido
- manage:mfa:unregister:totp
- manage:mfa:verify:*
- manage:mfa:verify:totp
- manage:key:*
- manage:key:readonly
- manage:key:get
- manage:key:attest
- manage:key:listRoles
- manage:key:list
- manage:key:history:tx:list
- manage:key:create
- manage:key:import
- manage:key:update:*
- manage:key:update:owner
- manage:key:update:policy
- manage:key:update:enabled
- manage:key:update:region
- manage:key:update:metadata
- manage:key:update:properties
- manage:key:update:editPolicy
- manage:key:delete
- manage:policy:*
- manage:policy:readonly
- manage:policy:create
- manage:policy:get
- manage:policy:list
- manage:policy:delete
- manage:policy:update:*
- manage:policy:update:owner
- manage:policy:update:name
- manage:policy:update:acl
- manage:policy:update:editPolicy
- manage:policy:update:metadata
- manage:policy:update:rule
- manage:policy:invoke
- manage:policy:wasm:*
- manage:policy:wasm:upload
- manage:policy:secrets:*
- manage:policy:secrets:get
- manage:policy:secrets:update:*
- manage:policy:secrets:update:values
- manage:policy:secrets:update:acl
- manage:policy:secrets:update:editPolicy
- manage:policy:buckets:*
- manage:policy:buckets:get
- manage:policy:buckets:list
- manage:policy:buckets:update:*
- manage:policy:buckets:update:owner
- manage:policy:buckets:update:acl
- manage:policy:buckets:update:metadata
- manage:contact:*
- manage:contact:readonly
- manage:contact:create
- manage:contact:get
- manage:contact:list
- manage:contact:delete
- manage:contact:update:*
- manage:contact:update:name
- manage:contact:update:addresses
- manage:contact:update:owner
- manage:contact:update:labels
- manage:contact:update:metadata
- manage:contact:update:editPolicy
- manage:contact:lookup:*
- manage:contact:lookup:address
- manage:policy:createImportKey
- manage:role:*
- manage:role:readonly
- manage:role:create
- manage:role:delete
- manage:role:get:*
- manage:role:attest
- manage:role:get:keys
- manage:role:get:keys:list
- manage:role:get:keys:get
- manage:role:get:users
- manage:role:list
- manage:role:update:*
- manage:role:update:enabled
- manage:role:update:policy
- manage:role:update:editPolicy
- manage:role:update:actions
- manage:role:update:key:*
- manage:role:update:key:add
- manage:role:update:key:remove
- manage:role:update:user:*
- manage:role:update:user:add
- manage:role:update:user:remove
- manage:role:history:tx:list
- manage:identity:*
- manage:identity:readonly
- manage:identity:verify
- manage:identity:add
- manage:identity:remove
- manage:identity:list
- manage:org:*
- manag
# --- truncated at 32 KB (62 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cubist/refs/heads/main/openapi/cubist-role-access-tokens-api-openapi.yml